The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T19:03:38.483Z
Reserved: 2024-03-01T16:17:36.665Z
Link: CVE-2024-2101
Updated: 2024-08-01T19:03:38.483Z
Status : Analyzed
Published: 2024-04-17T05:15:48.597
Modified: 2025-04-14T13:42:18.963
Link: CVE-2024-2101
No data.
OpenCVE Enrichment
No data.
Weaknesses